From 560c7ef9bc4411aaa0452e31594f27d610b1a91f Mon Sep 17 00:00:00 2001 From: Agent Date: Mon, 14 Sep 2026 16:10:10 -0400 Subject: [PATCH] document include_event body on POST /notify/:id The endpoint accepts an optional field for NIP-98 include_event support. When provided, the event is verified inline (id match + signature check). When omitted, the event is fetched from the relay. Documents the { ok: true, stored: boolean } response and dedup behavior. --- README.md | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 6738437..ba1ae0e 100644 --- a/README.md +++ b/README.md @@ -80,14 +80,27 @@ Response: { ok: true } NIP-9a relay push callback. Called by relays or NPB when matching events are found. ``` -Body: { id, relay } +Body: { id, relay, event? } Response: { ok: true, stored: boolean } Returns 404 if subscription not found or inactive. ``` -When the event is not found at the relay (e.g. it was deleted or never arrived), -the endpoint returns `{ ok: true, stored: false }` — the event is silently skipped -rather than erroring. The `stored` field is always present in a 200 response. +The optional `event` field supports NIP-98 `include_event` — relays can embed +the full event inline to bypass fetching. When `event` is provided: + +- `event.id` must match the `id` string, **and** the event signature must be + cryptographically valid (`verifyEvent` from nostr-tools). +- If either check fails, the endpoint returns **400** `{ error: 'Invalid event' }`. + +When `event` is omitted, the server fetches the event from the relay using +`id` and `relay`. If the relay has no matching event (deleted, expired, or +never published), the endpoint returns `{ ok: true, stored: false }` — the +event is silently skipped rather than erroring. + +After obtaining the event (from body or relay), it is stored in the local +database. If the event is already known (deduplication), `stored` is `false`; +otherwise `stored` is `true`. The `stored` field is always present in a 200 +response. ### GET /confirm?token=... Confirm email address via link from confirmation email. -- 2.45.2